VulnSea

Tagged “maven”

CVEs tagged maven, newest first.

321 CVEsRSS

CVE-2026-55559Critical· 9.8
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templat…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.78%via NVD
CVE-2026-55565Critical· 9.9
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source c…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.65%via NVD
CVE-2026-55566Medium· 4.3
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.38%via NVD
CVE-2026-55425Medium· 5.0
1mo ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleSe…

▾ Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.41%via NVD
CVE-2026-55511Critical· 9.1PoC
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fil…

▾ Abyssalyamcs · org.yamcs:yamcs-coreEPSS 0.68%via NVD
CVE-2026-55521High· 8.8
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and T…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.52%via NVD
CVE-2026-55545Medium· 6.5
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.45%via NVD
CVE-2026-55547Medium· 4.3
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.jav…

▾ Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.34%via NVD
CVE-2026-55549Medium· 6.5PoC
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping b…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 1.3%via NVD
CVE-2026-55552High· 7.5
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the…

▾ Twilightyamcs · org.yamcs:yamcs-coreEPSS 0.55%via NVD
CVE-2026-54556High
1mo ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory denial of service in the Ember backend with HTTP/2 enabled. The Hpack wrapper in ember-core/shared/s…

▾ Twilighthttp4s · org.http4s:http4s-ember-core_2.12EPSS 0.52%via NVD
CVE-2026-54550High· 7.4
1mo ago

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.j…

▾ Twilightcodehaus · org.codehaus.izpack:izpack-installerEPSS 0.45%via NVD
CVE-2026-54049High· 8.7
1mo ago

Sakai Conversations has a Stored XSS Issue

Sakai Conversations has a Stored XSS Issue

▾ Twilightsakaiproject · org.sakaiproject.conversations:sakai-conversations-implvia GHSA
CVE-2026-76904Critical· 9.8PoC
1mo ago

GeoTools is an open source Java library that provides tools for geospatial data

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataS…

▾ Abyssalgeotools · org.geotools.jdbc:gt-jdbc-postgisEPSS 2.4%via NVD
CVE-2026-63490High· 7.5
1mo ago

Handlebars.java provides logic-less and semantic Mustache templates with Java

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader w…

▾ Twilightgithub · com.github.jknack:handlebars-springmvcEPSS 0.69%via NVD
CVE-2026-61798High· 8.1
1mo ago

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringsslvia GHSA
CVE-2026-61799Medium· 5.3
1mo ago

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash

▾ Sunlitnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-63124High· 7.5
1mo ago

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-61827High
1mo ago

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-63202High· 7.5
1mo ago

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-75596High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/mai…

▾ Twilightnetty · nettyEPSS 0.69%via NVD
CVE-2026-75595Critical· 9.1
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…

▾ Midnightnetty · nettyEPSS 0.46%via NVD
CVE-2024-45747High· 7.2
1mo ago

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

▾ Twilightgeoserver · org.geoserver:gs-mainvia GHSA
CVE-2026-55839High· 8.7
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaS…

▾ Twilightkestra · io.kestra:kestraEPSS 0.43%via NVD
CVE-2026-69220High
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReade…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.73%via NVD
CVE-2026-69219High· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.73%via NVD
CVE-2026-63337High· 8.8
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted syst…

▾ Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.56%via NVD
CVE-2026-63335Medium
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java proces…

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.52%via NVD
CVE-2026-63336Medium
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) …

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.31%via NVD
CVE-2026-61634Low· 7.5
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/r…

▾ Sunlitrabbitmq · com.rabbitmq:amqp-clientEPSS 0.49%via NVD
CVEs tagged “maven” — page 4 · VulnSea